Why Should I Care? โ 2026-08-31 | ๐ด 10 HIGH ยท ๐ก 8 MEDIUM ยท ๐ต 73 RADAR ยท โช 54 FILTERED
๐ Briefing โ 2026-08-31
91 vendor intel items scanned | ๐ด 10 HIGH | ๐ก 8 MEDIUM | ๐ต 73 RADAR | โช 54 FILTERED
๐ด Critical โ action required:
- CISA Adds One Known Exploited Vulnerability to Catalog (CVE-2026-21962) โ Yes, if you run Oracle HTTP Server or Oracle WebLogic Server Proxy Plug-in: improper access control allows unauthorized access, actively exploited in the wild.
- CISA Adds One Known Exploited Vulnerability to Catalog (CVE-2026-60004) โ Yes, if you run Gitea versions 1.15.0 - 1.15.5, 1.16.0 - 1.16.2: code injection vulnerability, actively exploited in the wild.
- CISA Adds Six Known Exploited Vulnerabilities to Catalog (CVE-2015-3246, CVE-2015-5287, CVE-2019-1068, CVE-2021-23758, CVE-2022-0995, CVE-2026-8452) โ Yes, if you run any of the affected versions of Red Hat, Microsoft SQL Server, Ajax.NET Professional, Linux Kernel, or Citrix NetScaler: these vulnerabilities are actively exploited and pose significant risks.
- All-Line Equipment Company Fuel-Boss (CVE-2018-19518, CVE-2019-11043) โ Yes, if you run All-Line Equipment Company Fuel-Boss V1 Standard, Portal, Master/Slave, or Backflush Systems with PHP_7.1.5: unauthenticated RCE, potentially exploited.
- CISA Adds Three Known Exploited Vulnerabilities to Catalog (CVE-2023-49105, CVE-2026-53362, CVE-2026-66384) โ Yes, if you run any of the affected versions of ownCloud, Linux Kernel, or JFrog Artifactory: these vulnerabilities are actively exploited and pose significant risks.
- FURUNO FA-50 Class B AIS Transponder (CVE-2026-59769) โ Yes, if you run any version of FURUNO FA-50 Class B AIS Transponder: hard-coded credentials and missing authentication allow attackers to alter device settings.
- Ebyte NE2-D11 (CVE-2026-73125, CVE-2026-73809, CVE-2026-73839) โ Yes, if you run Ebyte NE2-D11 Firmware FW-9167-0-11: critical vulnerabilities allow unauthorized access, sensitive data disclosure, and device disruption.
- Applied Systems Engineering ASE2000 V2 Communications Test Set (CVE-2018-1285, CVE-2026-18717) โ Yes, if you run Applied Systems Engineering ASE2000 V2 versions 2.25-2.37: critical vulnerabilities allow arbitrary file access, network requests, and TLS interception.
- Ebyte NA111-M (CVE-2026-73125, CVE-2026-76179, CVE-2026-75814, CVE-2026-76940, CVE-2026-77966, CVE-2026-73809, CVE-2026-71187, CVE-2026-75548, CVE-2026-69658, CVE-2026-76133, CVE-2026-73819, CVE-2026-77975, CVE-2026-77977) โ Yes, if you run Ebyte NA111-M Firmware 9013-2-17: multiple critical vulnerabilities allow unauthenticated access and full device compromise.
- Xiiaozet LK100W (CVE-2026-78037, CVE-2026-78239, CVE-2026-76943) โ Yes, if you run Xiiaozet LK100W <2.1.240: unauthenticated RCE, OS command injection, and authentication bypass.
Everything else can wait.
๐ก Medium โ review when time permits:
- Zoneminder โ Yes, if you run Zoneminder 1.37.48 or 1.38.3: authenticated users can execute arbitrary commands on your server, leading to full Remote Code Execution (RCE).
- Rently Smart Home โ Yes, if you run Rently Smart Home <=20.1.0: attackers can access sensitive information and override user permissions, including the Master Pin.
- Bendix EC80 Brake ECU โ Yes, if you run any of the affected Bendix EC80 Brake ECU versions: an attacker can disable critical vehicle functions like ABS and steering assist, potentially causing a crash.
- PayRange API โ Yes, if you run any version of PayRange API: unauthenticated access to sensitive information and potential device modification, actively exploitable.
- Siemens SIMATIC IoT2050 Advanced โ Yes, if you run SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) versions < 4.3.4.1: unauthenticated attackers can execute arbitrary code with maximum privileges.
- Mitsubishi Electric Multiple FA Products (Update D) โ Yes, if you run any of the affected Mitsubishi Electric CC-Link IE TSN modules <=09: remote attackers can cause a DoS, timeout, or communication delay.
- Mitsubishi Electric CNC Series (Update A) โ Yes, if you run any affected version of Mitsubishi Electric CNC Series (Update A): unpatched systems can be remotely crashed, causing a denial-of-service.
- Vulnerability in OpenSSL library โ Yes, if you run Fortinet products using affected OpenSSL versions: unpatched systems can be made unresponsive via crafted certificates, leading to a denial of service.
๐ต 15 items on the radar โ see below โ
Why Should I Care? ๐ด HIGH โ Handle Now
CISA Adds One Known Exploited Vulnerability to Catalog
CISA Advisories [CISA KEV] | CVE-2026-21962
โ Why Should I Care?
Yes, if you run Oracle HTTP Server or Oracle WebLogic Server Proxy Plug-in: improper access control allows unauthorized access, actively exploited in the wild. Patch now.
๐ฏ Affected versions: Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in versions affected
๐ญ In plain English:
Your web server or proxy plug-in has a flaw that lets attackers sneak in without proper credentials. They can access sensitive data or control your server, causing serious disruptions. For example, an attacker could steal customer data or redirect traffic to malicious sites.
๐ง Prerequisites:
- The server or plug-in is accessible from the internet
- No proper access control measures are in place
โฑ Urgency: High urgency due to active exploitation in the wild.
๐ก Context: The access control mechanisms in the server or plug-in are improperly configured, allowing unauthorized users to bypass security checks.
CISA Adds One Known Exploited Vulnerability to Catalog
CISA Advisories [CISA KEV] | CVSS 9.8 | CVE-2026-60004
โ Why Should I Care?
Yes, if you run Gitea versions 1.15.0 - 1.15.5, 1.16.0 - 1.16.2: code injection vulnerability, actively exploited in the wild. Patch now.
๐ฏ Affected versions: Gitea 1.15.0 - 1.15.5, 1.16.0 - 1.16.2
Not affected: Gitea 1.17.0 and later
๐ญ In plain English:
An attacker can inject malicious code into your Gitea server, allowing them to execute arbitrary commands on your system. For example, they could upload a backdoor, steal your source code, or take control of your server without you knowing.
๐ง Prerequisites:
- Gitea server is running an affected version
- Attacker has access to the Gitea web interface
โฑ Urgency: High urgency due to active exploitation in the wild.
๐ก Context: The vulnerability allows attackers to inject malicious code through a specific input field, which is then executed by the server.
โ Fixed in: 1.17.0, 1.16.3, 1.15.6
CISA Adds Six Known Exploited Vulnerabilities to Catalog
CISA Advisories [CISA KEV] | CVSS N/A | CVE-2015-3246, CVE-2015-5287, CVE-2019-1068, CVE-2021-23758, CVE-2022-0995, CVE-2026-8452
โ Why Should I Care?
Yes, if you run any of the affected versions of Red Hat, Microsoft SQL Server, Ajax.NET Professional, Linux Kernel, or Citrix NetScaler: these vulnerabilities are actively exploited and pose significant risks.
๐ฏ Affected versions: Red Hat Libuser, Red Hat Automatic Bug Reporting Tool, Microsoft SQL Server, Ajax.NET Professional, Linux Kernel, Citrix NetScaler ADC and NetScaler Gateway
๐ญ In plain English:
These vulnerabilities allow attackers to take control of your systems, escalate privileges, or execute arbitrary code. For example, an attacker could exploit a flaw in Microsoft SQL Server to run any command on your server, potentially stealing data or installing malware.
๐ง Prerequisites:
- Running an affected version of the software
- No specific prerequisites mentioned
โฑ Urgency: High urgency due to active exploitation in the wild.
All-Line Equipment Company Fuel-Boss
CISA Advisories [CISA KEV] | CVSS 8.7 | CVE-2018-19518, CVE-2019-11043
โ Why Should I Care?
Yes, if you run All-Line Equipment Company Fuel-Boss V1 Standard, Portal, Master/Slave, or Backflush Systems with PHP_7.1.5: unauthenticated RCE, potentially exploited. Patch now.
๐ฏ Affected versions: Fuel-Boss V1 Standard: >=|<=PHP_7.1.5_7.1.5, Fuel-Boss V1 Portal: >=|<=PHP_7.1.5_7.1.5, Fuel-Boss V1 Master/Slave: >=|<=PHP_7.1.5_7.1.5, Fuel-Boss V1 Backflush Systems: >=|<=PHP_7.1.5_7.1.5
๐ญ In plain English:
Your Fuel-Boss system can be remotely controlled by attackers who can inject commands or overflow buffers, allowing them to execute arbitrary code. This means an attacker could take over your system, change settings, or even steal data without you knowing.
๐ง Prerequisites:
- Unpatched PHP_7.1.5 version
- Access to the system via IMAP or FPM
โฑ Urgency: High urgency due to the potential for remote code execution and the lack of patches for some versions.
๐ก Context: The system fails to properly sanitize input for IMAP commands and buffer sizes, allowing attackers to inject commands or overflow buffers to execute arbitrary code.
โ Fixed in: Not specified for all versions
CISA Adds Three Known Exploited Vulnerabilities to Catalog
CISA Advisories [CISA KEV] | CVE-2023-49105, CVE-2026-53362, CVE-2026-66384
โ Why Should I Care?
Yes, if you run any of the affected versions of ownCloud, Linux Kernel, or JFrog Artifactory: these vulnerabilities are actively exploited and pose significant risks.
๐ฏ Affected versions: ownCloud 2.0.x - 2.0.18, Linux Kernel 5.10.x - 5.19.x, JFrog Artifactory 7.20.x - 7.20.12
Not affected: ownCloud 2.1.x and above, Linux Kernel 6.0.x and above, JFrog Artifactory 7.21.x and above
๐ญ In plain English:
An attacker can exploit these vulnerabilities to gain unauthorized access to your systems, potentially taking full control. For example, if you use ownCloud, an attacker could log in without credentials and access all your files. If you use Linux Kernel, they could execute arbitrary code on your system. If you use JFrog Artifactory, they could access sensitive files and directories.
๐ง Prerequisites:
- Running affected versions of ownCloud
- Running affected versions of Linux Kernel
- Running affected versions of JFrog Artifactory
โฑ Urgency: High urgency due to active exploitation in the wild.
๐ก Context: The vulnerabilities include improper authentication, unspecified kernel issues, and improper directory restrictions, allowing attackers to bypass security measures and gain unauthorized access.
โ Fixed in: ownCloud 2.1.0, Linux Kernel 6.0.0, JFrog Artifactory 7.21.0
FURUNO FA-50 Class B AIS Transponder
CISA Advisories | CVSS 9.1 | CVE-2026-59769
โ Why Should I Care?
Yes, if you run any version of FURUNO FA-50 Class B AIS Transponder: hard-coded credentials and missing authentication allow attackers to alter device settings. Patch now if possible.
๐ฏ Affected versions: FURUNO FA-50 Class B AIS Transponder: vers:all/*
๐ญ In plain English:
Your AIS transponder has a secret password that anyone can use to change its settings. An attacker who gains access to your ship's network can alter these settings, potentially disabling safety features or misreporting your ship's position.
๐ง Prerequisites:
- Knowledge of hard-coded credentials
- Access to the in-vessel network
โฑ Urgency: High urgency due to the critical nature of the device and the potential for unauthorized changes to safety-critical settings.
๐ก Context: The device uses hard-coded credentials and lacks proper authentication mechanisms for critical functions, allowing unauthorized users to alter settings.
Ebyte NE2-D11
CISA Advisories | CVSS 9.8 | CVE-2026-73125, CVE-2026-73809, CVE-2026-73839
โ Why Should I Care?
Yes, if you run Ebyte NE2-D11 Firmware FW-9167-0-11: critical vulnerabilities allow unauthorized access, sensitive data disclosure, and device disruption. Patch urgently.
๐ฏ Affected versions: Ebyte NE2-D11 Firmware FW-9167-0-11
๐ญ In plain English:
Your device's web management interface is wide open. An attacker can log in without a password, steal sensitive data, change settings, and even crash the device. Imagine someone remotely changing your firewall rules or stealing your login credentials just by sniffing network traffic.
๐ง Prerequisites:
- Device running Ebyte NE2-D11 Firmware FW-9167-0-11
- Network access to the device
โฑ Urgency: High urgency due to the critical nature of the vulnerabilities and the potential for unauthorized access and disruption.
๐ก Context: The device lacks proper authentication mechanisms and encrypts sensitive data improperly, allowing attackers to exploit these flaws easily.
Applied Systems Engineering ASE2000 V2 Communications Test Set
CISA Advisories | CVSS 9.8 | CVE-2018-1285, CVE-2026-18717
โ Why Should I Care?
Yes, if you run Applied Systems Engineering ASE2000 V2 versions 2.25-2.37: critical vulnerabilities allow arbitrary file access, network requests, and TLS interception. Patch now.
๐ฏ Affected versions: ASE2000 V2 versions 2.25-2.37
Not affected: 2.38 and later
๐ญ In plain English:
An attacker can read or write any file on your device, make it send network requests, or intercept secure communications. For example, an attacker could steal sensitive files, send fake commands to your network, or eavesdrop on your secure communications without you knowing.
๐ง Prerequisites:
- Access to the device's file system or network communication
- The device is running an affected version
โฑ Urgency: High urgency due to the critical nature of the vulnerabilities and potential for active exploitation.
๐ก Context: The device improperly handles XML external entity references and fails to validate TLS certificates correctly, allowing for unauthorized access and interception.
โ Fixed in: 2.38
Ebyte NA111-M
CISA Advisories | CVSS 9.8 | CVE-2026-73125, CVE-2026-76179, CVE-2026-75814, CVE-2026-76940, CVE-2026-77966, CVE-2026-73809, CVE-2026-71187, CVE-2026-75548, CVE-2026-69658, CVE-2026-76133, CVE-2026-73819, CVE-2026-77975, CVE-2026-77977
โ Why Should I Care?
Yes, if you run Ebyte NA111-M Firmware 9013-2-17: multiple critical vulnerabilities allow unauthenticated access and full device compromise. Patch urgently.
๐ฏ Affected versions: NA111-M Firmware 9013-2-17
๐ญ In plain English:
Your device's web management interface lacks proper authentication, allowing anyone to access sensitive configuration information, modify settings, or disrupt the device. An attacker could impersonate an admin, change settings, and take full control of your device without any trace.
๐ง Prerequisites:
- Device running Firmware 9013-2-17
- No patch applied
โฑ Urgency: High urgency due to multiple critical vulnerabilities that allow full device compromise.
๐ก Context: The web management interface does not consistently enforce authentication before granting access to administrative functionality, and authentication tokens are insufficiently protected.
Xiiaozet LK100W
CISA Advisories | CVSS 9.8 | CVE-2026-78037, CVE-2026-78239, CVE-2026-76943
โ Why Should I Care?
Yes, if you run Xiiaozet LK100W <2.1.240: unauthenticated RCE, OS command injection, and authentication bypass. Actively exploitable.
๐ฏ Affected versions: Xiiaozet LK100W <2.1.240
๐ญ In plain English:
Your device's web interface allows attackers to run any command on the device, bypass authentication, and take full control. An attacker could steal sensitive data, alter device settings, or use the device for malicious activities without your knowledge.
๐ง Prerequisites:
- Device version <2.1.240
โฑ Urgency: High urgency due to the critical nature of the vulnerabilities and potential for active exploitation.
๐ก Context: The device's web interface fails to properly sanitize input, allowing for OS command injection, and has critical functions that do not require authentication.
โ Fixed in: 2.1.240
Why Should I Care? ๐ก MEDIUM (8)
Zoneminder
CISA Advisories | CVSS 8.8 | CVE-2026-76060
โ Why Should I Care?
Yes, if you run Zoneminder 1.37.48 or 1.38.3: authenticated users can execute arbitrary commands on your server, leading to full Remote Code Execution (RCE). Patch now.
๐ฏ Affected versions: Zoneminder 1.37.48, 1.38.3
๐ญ In plain English:
An authenticated user can inject malicious commands into the server through the event export feature, allowing them to take full control of your server. For example, an attacker could log in with a valid account and execute commands to steal data, install malware, or shut down services.
๐ง Prerequisites:
- Authenticated user with View Events permission
โฑ Urgency: High urgency due to the potential for full server control and active exploitation.
๐ก Context: The exportFile HTTP request parameter is passed unsanitized into a shell command via PHP's exec(), allowing command injection.
โ Fixed in: 1.38.3
Rently Smart Home
CISA Advisories | CVSS 8.1 | CVE-2026-75960
โ Why Should I Care?
Yes, if you run Rently Smart Home <=20.1.0: attackers can access sensitive information and override user permissions, including the Master Pin.
๐ฏ Affected versions: Rently Smart Home <=20.1.0
๐ญ In plain English:
Your smart home system has a weak password protection issue. An attacker could steal your Master Pin and take full control of your smart home devices, changing settings and permissions without your knowledge.
๐ง Prerequisites:
- Smart Home version <=20.1.0
โฑ Urgency: High urgency due to the potential for unauthorized access and control over smart home devices.
๐ก Context: The system stores credentials in an insecure manner, allowing unauthorized access to sensitive information.
โ Fixed in: 20.1.1
Bendix EC80 Brake ECU
CISA Advisories | CVSS 7.5 | CVE-2026-67560, CVE-2026-68967
โ Why Should I Care?
Yes, if you run any of the affected Bendix EC80 Brake ECU versions: an attacker can disable critical vehicle functions like ABS and steering assist, potentially causing a crash.
๐ฏ Affected versions: EC80ESP+ J1708 Z228999, EC80ESP+ 6S/6M Z228999, EC80ESP+ PLC Z228999, EC80ESP+ 2nd CAN Z228999, EC80ESP+ Integrated TPMS Z228999, EC80ESP 6S/6M Z266494, EC80ESP PLC Z266494, EC80ESP 2nd CAN Z266494, EC80ESP CAN Gateway Z266494, EC80ESP 4S/4M Z286098, EC80ESP PLC Z286098
๐ญ In plain English:
Your vehicle's brake control unit has a flaw that allows an attacker to send malicious data over the CAN bus, potentially disabling critical safety features like ABS and steering assist. This could lead to a loss of vehicle control and a crash.
๐ง Prerequisites:
- Access to the CAN bus
โฑ Urgency: High urgency due to the potential for loss of vehicle control and safety features.
๐ก Context: The firmware contains a stack-based buffer overflow and out-of-bounds write vulnerabilities, allowing an attacker to inject arbitrary CAN bus traffic and execute arbitrary code.
โ Fixed in: Z300822, Z302578, Z302579
PayRange API
CISA Advisories | CVSS 8.8 | CVE-2026-18965
โ Why Should I Care?
Yes, if you run any version of PayRange API: unauthenticated access to sensitive information and potential device modification, actively exploitable.
๐ฏ Affected versions: PayRange API vers:all/*
๐ญ In plain English:
Your PayRange API is missing proper security checks, allowing anyone to access sensitive information and potentially alter device settings, leading to a denial of service or image tampering. An attacker could view your financial data or change device configurations without your knowledge.
๐ง Prerequisites:
- No authentication required
โฑ Urgency: High urgency due to the potential for unauthenticated access and active exploitation.
๐ก Context: The management endpoints lack proper authorization checks, allowing unauthorized access to sensitive information and device control.
Siemens SIMATIC IoT2050 Advanced
CISA Advisories | CVSS 10 | CVE-2026-58115
โ Why Should I Care?
Yes, if you run SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) versions < 4.3.4.1: unauthenticated attackers can execute arbitrary code with maximum privileges. Patch now.
๐ฏ Affected versions: SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) < 4.3.4.1
๐ญ In plain English:
Your IoT2050 device has a backdoor that lets anyone on the internet log in and run any command they want on your device. An attacker could use this to take full control of your device, steal data, or even brick it.
๐ง Prerequisites:
- Node-RED must be installed
- Device must be accessible from the internet
โฑ Urgency: High urgency due to the critical nature of the vulnerability and the potential for unauthenticated remote code execution.
๐ก Context: The Node-RED HTTP interface does not enforce authentication, allowing unauthenticated access to programming nodes that can execute system commands.
โ Fixed in: 4.3.4.1
Mitsubishi Electric Multiple FA Products (Update D)
CISA Advisories | CVE-2025-3511
โ Why Should I Care?
Yes, if you run any of the affected Mitsubishi Electric CC-Link IE TSN modules <=09: remote attackers can cause a DoS, timeout, or communication delay. Patch now.
๐ฏ Affected versions: Mitsubishi Electric CC-Link IE TSN modules <=09 (specific models listed in advisory)
๐ญ In plain English:
An attacker can send a specially crafted packet to your Mitsubishi Electric CC-Link IE TSN modules, causing them to stop working, time out, or delay communication. This means your industrial control systems could freeze or become unresponsive, potentially disrupting your operations.
๐ง Prerequisites:
- The attacker must be able to send UDP packets to the affected module.
โฑ Urgency: Moderately urgent due to the potential for operational disruption caused by DoS conditions.
Mitsubishi Electric CNC Series (Update A)
CISA Advisories | CVSS 5.9 | CVE-2025-2399
โ Why Should I Care?
Yes, if you run any affected version of Mitsubishi Electric CNC Series (Update A): unpatched systems can be remotely crashed, causing a denial-of-service. Apply the fix now.
๐ฏ Affected versions: Mitsubishi Electric M800VW (BND-2051W000) <=BB, M800VS (BND-2052W000) <=BB, M80V (BND-2053W000) <=BB, M80VW (BND-2054W000) <=BB, M800W (BND-2005W000) <=FM, M800S (BND-2006W000) <=FM, M80 (BND-2007W000) <=FM, M80W (BND-2008W000) <=FM, E80 (BND-2009W000) <=FM, C80 (BND-2036W000) vers:all/*, M750VW (BND-1015W002) <=LJ, M730VW (BND-1015W000) <=LJ, M720VW (BND-1015W000) <=LJ, M750VS (BND-1012W002) <=LJ, M730VS (BND-1012W000) <=LJ, M720VS (BND-1012W000) <=LJ, M70V (BND-1018W000) <=LJ, E70 (BND-1022W000) <=LJ
๐ญ In plain English:
Your CNC machine can be made to crash remotely, causing it to stop working. An attacker could send a bad command that makes the machine freeze, stopping production until it's fixed.
๐ง Prerequisites:
- TCP port 683 must be accessible from the attacker's location
โฑ Urgency: Medium urgency: this vulnerability can cause a denial-of-service, but does not allow for data theft or remote code execution.
๐ก Context: The software fails to properly validate input, allowing an attacker to send a specially crafted packet that triggers an out-of-bounds read.
โ Fixed in: BC or later for M800VW, M800VS, M80V, M80VW, FN or later for M800W, M800S, M80, M80W, E80
Vulnerability in OpenSSL library
Fortinet PSIRT | CVSS 7.5 | CVE-2022-0778
โ Why Should I Care?
Yes, if you run Fortinet products using affected OpenSSL versions: unpatched systems can be made unresponsive via crafted certificates, leading to a denial of service.
๐ฏ Affected versions: FortiOS 7.0.x - 7.2.13, 7.4.0 - 7.4.2
๐ญ In plain English:
An attacker can send your Fortinet device a specially crafted certificate that makes it freeze and stop working. This means your security device could become unresponsive, leaving your network vulnerable until it's fixed.
๐ง Prerequisites:
- The device must be configured to parse externally supplied certificates
โฑ Urgency: Moderately urgent due to the potential for denial of service attacks, though no active exploitation has been reported.
๐ก Context: The BN_mod_sqrt() function in OpenSSL has a bug that causes it to loop indefinitely when processing certain invalid certificates, leading to a denial of service.
โ Fixed in: 7.0.14, 7.2.14, 7.4.3
Why Should I Care? ๐ต On the Radar (73)
- Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data (The Hacker News) โ A critical flaw in Oracle WebLogic Server and Oracle HTTP Server allows attackers to access and modify critical data without authentication. This means that if your enterprise uses these products, your data is at risk of unauthorized access and manipulation.
- Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload (The Hacker News) โ A severe security flaw in Gitea allows attackers to execute arbitrary code, leading to potential cryptojacking. If you use Gitea, you need to update to version 1.27.1 to mitigate this risk.
- CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs (The Hacker News) โ CISA has added six actively exploited vulnerabilities to its KEV catalog, affecting a range of products including Citrix NetScaler, Microsoft SQL Server, Linux, and others. These vulnerabilities could allow attackers to execute code, escalate privileges, or cause denial of service.
- ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body (The Hacker News) โ A critical security flaw in ownCloud was exploited to steal sensitive nuclear records from a Philippine research body. This means that if you're using ownCloud, your files could be at risk if you haven't patched the vulnerability.
- Weedhack Malware Spreads via Fake Minecraft Clients and SEO Poisoning (The Hacker News) โ Weedhack malware is spreading through fake Minecraft client websites and file hosting services, tricking users into downloading malicious software. This can lead to data theft and system compromise.
- Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows (The Hacker News) โ A phishing campaign called Mirage2FA has affected 4,500 companies in the US and EU by exploiting Microsoft 365 login flows and bypassing two-factor authentication. This means attackers can hijack user sessions and access sensitive corporate data.
- Marimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit Mode (The Hacker News) โ Marimo Notebook had a flaw that allowed attackers to run commands on your system before any cells were executed, which could lead to unauthorized access or data breaches.
- Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code (The Hacker News) โ Two unpatched vulnerabilities in Kaltura's HTML5 video player library could allow attackers to read files and execute code on your server. This means that sensitive data like database credentials could be exposed, and attackers could potentially take control of your server.
- Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE (The Hacker News) โ Vercel has patched two critical vulnerabilities in Next.js that allow unauthenticated remote code execution. One affects Windows servers, and the other involves AVIF image files. Both can lead to full server compromise.
- PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions (The Hacker News) โ A critical vulnerability in PaperCut NG and MF print management software is being actively exploited. The company has released emergency patches for v25 and v26, but all users should restrict access to trusted IP addresses immediately.
- Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server (The Hacker News) โ A critical security flaw in cPanel and WHM allows authenticated users to create arbitrary files on the server, potentially gaining root access. This means a single hosting customer could take control of the entire server, posing a significant risk to security and operations.
- China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access (The Hacker News) โ ZBT routers and some white-labeled devices have two critical vulnerabilities that allow attackers to gain root access without authentication. This means anyone can take control of your network devices.
- Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL (The Hacker News) โ ServiceNow has patched four critical flaws, three of which are rated CVSS 10.0, allowing unauthenticated attackers to execute code and SQL. This means attackers could gain full control over your ServiceNow instances, impacting data integrity and availability.
- Two Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE, One Starts Over Bluetooth (The Hacker News) โ Two critical vulnerabilities in Unitree G1 EDU humanoid robots allow attackers to execute code with root privileges, one via Bluetooth and the other over the network. This could lead to unauthorized control of the robot.
- Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication (The Hacker News) โ Attackers can exploit two flaws in PaperCut NG and MF to execute code without authentication, potentially taking control of your PaperCut instances. This means an attacker could remotely execute commands on your server, compromising your network.
โช 54 low-priority items filtered.
๐ฆ Aggregated and triaged by Donna AI | Sources: 9 vendor feeds | CISA KEV